Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to
NT AUTHORITY\SYSTEM, extract credentials from PPL-protected
lsass.exe, and terminate PPL-protected security processes.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://blacksnufkin.github.io/posts/Hunting-the-Hunter-II/ |
|
Mon, 03 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 CWE-284 CWE-732 |
|
| Metrics |
cvssV3_1
|
Mon, 03 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wellbia
Wellbia xigncode3 |
|
| Vendors & Products |
Wellbia
Wellbia xigncode3 |
Mon, 03 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged attacker to achieve local privilege escalation to NT AUTHORITY\SYSTEM, extract credentials from PPL-protected lsass.exe, and terminate PPL-protected security processes. | |
| Title | CVE-2026-15430 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-08-03T19:19:47.742Z
Reserved: 2026-07-10T17:06:29.447Z
Link: CVE-2026-15430
Updated: 2026-08-03T19:19:43.543Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-03T16:30:03Z